From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Sun, 18 Jan 2026 17:25:13 -0800 Received: from mail-oi1-f184.google.com ([209.85.167.184]) by mail.fairlystable.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1vhe13-00026T-B2 for bitcoindev@gnusha.org; Sun, 18 Jan 2026 17:25:13 -0800 Received: by mail-oi1-f184.google.com with SMTP id 5614622812f47-45c879592fesf7397312b6e.0 for ; Sun, 18 Jan 2026 17:25:12 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1768785906; x=1769390706; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:x-original-sender :mime-version:subject:references:in-reply-to:message-id:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=LkN+A4nYgTe6nfHFgvGco+YSkjB4q75WEbyWNtqEA4Q=; b=hmdD1rjWOhp2Z1Dbn69vGq3MhSRzT/59xwkhTfbDZkRTf01xOUEFmj3Wiy/Q610f+g mklZl5ADHlWgIZ6V9FjPRMffVfrrhm1Fwc5AfV674TyOKZSVoshXqqIH+cCSUa5erijl t5lBJbbLpK1KqwiDQd5P9KAFhR7nceaVJhY2ysOYd1Y6+QXv3O66gGm1uB3bvMQPCmAU FkMQ87Vdo/6hzsVOJk5gYVKD67a2AghCl94rtf2ECHxMhBkqWdBkMXTRvGGzpvEJyvuo Qbs+H3WD4xukbcysQhBOiXT2c3Ca3hsjUeyQabXc9lCzG/NgWoKqUlnhMnCj3AWmmZij S1aw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768785906; x=1769390706; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:x-original-sender :mime-version:subject:references:in-reply-to:message-id:to:from:date :x-beenthere:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=LkN+A4nYgTe6nfHFgvGco+YSkjB4q75WEbyWNtqEA4Q=; b=gquri8cO1LHYlbZv0CtztWiZ/Bdy6BU/uKPP+cG/Pzfi1+YNJzXHYCgy65vTWMcCK7 q9KxCE+gPLzTq5P8LNrIS32idfdTrYh3ejoyW8lb8fjZ/1raugTBVHfNhraaM0gqdBL+ /pbVJRV1hqtQG74xHlPUvpBQ5K4DXTEH/zWPWv8TxUFGY/QEGguTt6mKjsG36ezrG8dy WeoWAOXjaj2PCsPE0FXXFkuUUzdQTC3SS4r7JZ5y4oH43SEaQ7AeX5o5xZS3/CJt4+4V g00LtQQzlNEnaFE7gs2433U6f5scGH+5ZBTPUkmXwcQpHY7FSKpxmev8swMeaoD9JD0h 9uzA== X-Forwarded-Encrypted: i=1; AJvYcCVDI34joqDnp2lJncoLPv/h9eAGtjT39/qLrlB0sWyhbUwM2JZA59sga7R5Yej3BQZCxVJL1zvdBwhg@gnusha.org X-Gm-Message-State: AOJu0YzaTsg0AdupV6lDc9fFqTPh+OhNVR/ICEGBK/TggjOo9bK3MdhL EcG/dB33fvJlM8YJ0isA9hq0zcmEfocBrBB+7mteOwZhu7vXGcYHNMCU X-Received: by 2002:a05:6808:1a01:b0:45c:92e6:6f7b with SMTP id 5614622812f47-45c9d8c7cc1mr4251696b6e.49.1768785906294; Sun, 18 Jan 2026 17:25:06 -0800 (PST) X-BeenThere: bitcoindev@googlegroups.com; h="AV1CL+EGF5ezR1dhic4V5eDRobIFdiAhFZ6xvO5ectBjO2zD+w==" Received: by 2002:a05:6871:3a28:b0:3c9:732d:60f2 with SMTP id 586e51a60fabf-404289c4fc8ls2845299fac.1.-pod-prod-02-us; Sun, 18 Jan 2026 17:25:01 -0800 (PST) X-Received: by 2002:a05:6808:2291:b0:450:4782:2b57 with SMTP id 5614622812f47-45c9bfce0acmr4165566b6e.18.1768785901345; Sun, 18 Jan 2026 17:25:01 -0800 (PST) Received: by 2002:a05:690c:a4cc:20b0:792:7e2a:26c1 with SMTP id 00721157ae682-793c7c6f447ms7b3; Sun, 18 Jan 2026 17:12:37 -0800 (PST) X-Received: by 2002:a05:690c:c513:b0:78f:a7aa:b67e with SMTP id 00721157ae682-793c506d2a0mr82973187b3.0.1768785156869; Sun, 18 Jan 2026 17:12:36 -0800 (PST) Date: Sun, 18 Jan 2026 17:12:36 -0800 (PST) From: "'conduition' via Bitcoin Development Mailing List" To: Bitcoin Development Mailing List Message-Id: <58e6a5e3-8705-43f5-8187-724b8e3a62den@googlegroups.com> In-Reply-To: <34eaa8a5-69c1-4825-8f00-ff6de755ba09@gmail.com> References: <3e815d03-5e21-41ed-ba1a-4f9b2120a986n@googlegroups.com> <492feee7-e0da-4d4d-bb7a-e903b321a977n@googlegroups.com> <34eaa8a5-69c1-4825-8f00-ff6de755ba09@gmail.com> Subject: Re: [bitcoindev] Re: Hash-Based Signatures for Bitcoin's Post-Quantum Future MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_571808_894508046.1768785156492" X-Original-Sender: conduition@proton.me X-Original-From: conduition Reply-To: conduition Precedence: list Mailing-list: list bitcoindev@googlegroups.com; contact bitcoindev+owners@googlegroups.com List-ID: X-Google-Group-Id: 786775582512 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Score: -1.0 (-) ------=_Part_571808_894508046.1768785156492 Content-Type: multipart/alternative; boundary="----=_Part_571809_2041262617.1768785156492" ------=_Part_571809_2041262617.1768785156492 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hey Jonas, I've been busy over the holidays but just got around to reading your=20 delving post on SHRINCS. Big +1 from me, perhaps not in the exact form you= =20 propose - i suspect a more modular approach would make standardization=20 easier - But in principle this would be awesome to have as an option. It= =20 has pitfalls, but until more size-efficient stateless schemes like SQIsign= =20 mature, stateful HBS schemes are the smallest signatures available. Full=20 thoughts on delving here=20 =20 regards, conduition On Tuesday, December 16, 2025 at 3:30:58=E2=80=AFAM UTC-5 Jonas Nick wrote: > Hi Boris, > > Just to add to what Mike said: one of the most interesting questions is= =20 > whether > MPC considerations should inform parameter selection. As of right now, th= e > generic MPC approach seems rather impractical, but that shouldn't=20 > discourage > experimentation and further research. It's possible to imagine scenarios= =20 > where > 85-minute signing is acceptable. > > Moreover, stateful signature schemes like SHRINCS [0] only require a few= =20 > hashes > in the best case, which would make MPC-based N/N multisig significantly= =20 > more > tractable than with full SPHINCS+. However, since SHRINCS signatures are= =20 > already > small, the absolute space savings are smaller. > > [0]=20 > https://delvingbitcoin.org/t/shrincs-324-byte-stateful-post-quantum-signa= tures-with-static-backups/2158 > > Jonas > --=20 You received this message because you are subscribed to the Google Groups "= Bitcoin Development Mailing List" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to bitcoindev+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/bitcoindev/= 58e6a5e3-8705-43f5-8187-724b8e3a62den%40googlegroups.com. ------=_Part_571809_2041262617.1768785156492 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hey Jonas,

I've been busy over the holidays but just g= ot around to reading your delving post on SHRINCS. Big +1 from me, perhaps = not in the exact form you propose - i suspect a more modular approach would= make standardization easier - But in principle=C2=A0 this would be awesome= to have as an option. It has pitfalls, but until more size-efficient state= less schemes like SQIsign mature, stateful HBS schemes are the smallest sig= natures available. Full thoughts on delving here=C2=A0=C2=A0

= regards,
conduition

<= div dir=3D"auto" class=3D"gmail_attr">On Tuesday, December 16, 2025 at 3:30= :58=E2=80=AFAM UTC-5 Jonas Nick wrote:
Hi Boris,

Just to add to what Mike said: one of the most interesting questions is= whether
MPC considerations should inform parameter selection. As of right now, = the
generic MPC approach seems rather impractical, but that shouldn't d= iscourage
experimentation and further research. It's possible to imagine scen= arios where
85-minute signing is acceptable.

Moreover, stateful signature schemes like SHRINCS [0] only require a fe= w hashes
in the best case, which would make MPC-based N/N multisig significantly= more
tractable than with full SPHINCS+. However, since SHRINCS signatures ar= e already
small, the absolute space savings are smaller.

[0] https://delvingbitcoin.org/t/shr= incs-324-byte-stateful-post-quantum-signatures-with-static-backups/2158

Jonas

--
You received this message because you are subscribed to the Google Groups &= quot;Bitcoin Development Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an e= mail to bitcoind= ev+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/bitcoind= ev/58e6a5e3-8705-43f5-8187-724b8e3a62den%40googlegroups.com.
------=_Part_571809_2041262617.1768785156492-- ------=_Part_571808_894508046.1768785156492--